CVE-2026-24771

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, a Cross-Site Scripting (XSS) vulnerability exists in the `ErrorBoundary` component of the hono/jsx library. Under certain usage patterns, untrusted user-controlled strings may be rendered as raw HTML, allowing arbitrary script execution in the victim's browser. Version 4.11.7 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hono:hono:*:*:*:*:*:node.js:*:*

History

04 Feb 2026, 15:28

Type Values Removed Values Added
References () https://github.com/honojs/hono/commit/2cf60046d730df9fd0aba85178f3ecfe8212d990 - () https://github.com/honojs/hono/commit/2cf60046d730df9fd0aba85178f3ecfe8212d990 - Patch
References () https://github.com/honojs/hono/security/advisories/GHSA-9r54-q6cx-xmh5 - () https://github.com/honojs/hono/security/advisories/GHSA-9r54-q6cx-xmh5 - Vendor Advisory
CPE cpe:2.3:a:hono:hono:*:*:*:*:*:node.js:*:*
First Time Hono hono
Hono

27 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 20:16

Updated : 2026-02-04 15:28


NVD link : CVE-2026-24771

Mitre link : CVE-2026-24771

CVE.ORG link : CVE-2026-24771


JSON object : View

Products Affected

hono

  • hono
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')